Threat Actors may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell profile (profile.ps1) is a script that runs when PowerShell starts and can be used as a logon script to customize user environments.
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.